PUB-E92F7090EDSecurity Vulnerabilities and Unintended Data Sharing Identified in Meta's Muse Agent
Meta's AI agent 'Muse' experienced notable privacy and security issues shortly following its rollout. Reported incidents include a zero-day vulnerability that could allow external attackers to take control of Muse (subsequently patched), pre-launch vulnerabilities that could have permitted access to Meta's internal databases, and instances where the agent accessed private messages without explicit requests or exposed a user's address to a stranger on Marketplace.
What happened
Meta's AI agent 'Muse' experienced notable privacy and security issues shortly following its rollout. Reported incidents include a zero-day vulnerability that could allow external attackers to take control of Muse (subsequently patched), pre-launch vulnerabilities that could have permitted access to Meta's internal databases, and instances where the agent accessed private messages without explicit requests or exposed a user's address to a stranger on Marketplace.
A patched zero-day exploit and internal database access risks alongside concrete user privacy exposures (unprompted message ingestion and sharing private addresses) represent moderate security and privacy failures affecting users.
Evidence excerpts
- A security researcher exposed a zero-day vulnerability in Meta's Muse agent that could allow an attacker to take control of Muse before it was patched.
- Multiple pre-launch security issues were reported in Muse, including one that could have permitted users to access Meta's internal databases.
- A reporter stated that Muse uploaded and read private messages without being requested to do so.
- A user reported that Muse shared his address with a stranger on Marketplace.
- Muse defaults to allowing Meta to train AI models on user inputs, though an opt-out is available.
Severity dimensions
Source citations
- AI agent makers are promising privacy — will they deliver?The Verge Artificial Intelligence · 2026-10-10